IoT Gateway Enrollment via Management Service Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device management systems face security risks when administrators create and manage credentials for gateways, as this can expose sensitive information and compromise security.

Innovation Solution

A management service generates enrollment credentials limited to enrollment operations, which are provided to users for entry through a user interface, and uses cryptographic protocols like TLS for secure communication, ensuring that gateway credentials are not exposed to users and are stored securely on the gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an administrator creates and manages credentials for gateway authentication, then the gateway can be enrolled and managed securely, but the administrator's knowledge of credentials creates a security risk

Engineering Contradiction:
ImprovesecurityVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the credential management function from the administrator and relocates it to the management service. The management service generates credentials automatically and stores them securely, while the administrator only receives an enrollment token. This separation eliminates the security risk of credential exposure while maintaining the ability to enroll and manage gateways.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an enrollment token as an intermediary between the administrator and the gateway credentials. The administrator receives and inputs only the enrollment token, not the actual credentials. The management service uses this token to generate and manage the credentials securely, acting as a mediator that protects sensitive information from exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If enrollment credentials are provided to users for gateway enrollment, then the enrollment process can be completed, but the credentials may be exposed to users creating security vulnerabilities

Engineering Contradiction:
Improveenrollment processVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the enrollment credentials into two distinct parts: an enrollment token provided to the user and the actual gateway credentials kept secure by the management service. The user only handles the enrollment token for the enrollment process, while the sensitive credentials remain protected on the server side, eliminating exposure risk while maintaining operational ease.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enrollment token serves as an intermediary that enables the user to complete enrollment without exposing the actual credentials. The token is sufficient for the enrollment process but does not contain or reveal the sensitive gateway credentials, thus facilitating easy operation while preventing credential exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If administrators manage gateway credentials directly, then enrollment can be performed, but security risks increase due to credential exposure

Engineering Contradiction:
Improvegateway enrollment capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the sensitive credential management from the administrator's responsibilities and transfers it to the management service. The administrator retains the capability to enroll gateways through the simplified enrollment token process, while the security-critical credential generation and storage are handled automatically by the system, maintaining adaptability while improving security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11916911B2Gateway enrollment for Internet of Things device management
Publication Date: 2024.02.27 VMWARE INC
  • US11916911B2 patent drawing
  • US11916911B2 patent drawing
  • US11916911B2 patent drawing

AI summary

Disclosed are various examples for enrollment of gateway enrollment for Internet-of-Things (IoT) device management. In some examples, a client device receives a gateway management installation package from a management service. The client device installs a gateway management application to the gateway device using the installation package. Enrollment credentials are entered through a user interface generated using the gateway management application and shown on the client device. The client device instructs the gateway management application enroll the gateway device with the management service. Usage of the enrollment credentials prevents a user from being exposed to gateway credentials that authenticate communications between the gateway device and the management service.